AIPolicyTracker

Free global AI law and policy tracker

From regulation to evidence.

Track AI regulations and obligations. Connect them to governance controls, risks and evidence. Every claim links to its source.

AI policy, verified at the source. Every record links its official text and states when a person last checked it.

Latest AI policy updates

All updates

The six most recent dated changes to AI laws and guidance, each linked to the record it changed and to its official source.

RSS · Updates hub · Weekly digest

Where should you start?

All roles, sectors and use cases

Start from your role, sector or use case. Each page lists every recorded duty that names your situation, the controls that meet them and the evidence a reviewer would expect. It is generated from the records, so it moves when they do.

Jurisdictions

All jurisdictions

The jurisdictions the editors feature, each with its region, the number of instruments on record and a summary of where its AI rules stand.

The instruments the editors feature, each with its status, whether it binds, when a person last checked it and a link to its official text.

Colorado (United States) Act / statute Repealed Binding

Colorado AI Act

Colorado Senate Bill 24-205: Consumer Protections for Artificial Intelligence (Colorado AI Act)

The Colorado AI Act requires developers and deployers of high-risk AI systems to use reasonable care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination. High-risk systems are those that make, or are a substantial factor in making, consequential decisions about education, employment, financial or lending services, essential government services, healthcare, housing, insurance or legal services. Deployers must run risk-management programmes and impact assessments, notify consumers, and explain adverse decisions; developers must document systems and disclose known risks.

Adopted 17 May 2024 Checked Official source
Colorado (United States) Act / statute Adopted Binding

Colorado ADMT law (SB 26-189)

Colorado Senate Bill 26-189: Automated Decision-Making Technology (replacement of the Colorado AI Act)

SB 26-189 replaces the Colorado AI Act's regulation of "high-risk" AI systems with duties that attach when automated decision-making technology materially influences a consequential decision about a Colorado consumer in areas such as employment, lending, housing, education, healthcare, insurance and government services. It drops the earlier duty of reasonable care, the mandatory risk-management programme, impact assessments and Attorney General notification, and substitutes advance notice to the consumer, disclosure after an adverse outcome, meaningful human review, three-year record keeping and developer documentation obligations.

Applies from 1 Jan 2027 Checked Official source
Council of Europe Act / statute Adopted Binding

Framework Convention on AI (CETS 225)

Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (CETS No. 225)

The first international treaty on AI. Parties must adopt or maintain measures so that activities within the lifecycle of AI systems are consistent with human rights, democracy and the rule of law, covering public authorities and actors on their behalf and, by choice of approach, private actors. It sets principles (human dignity and autonomy, transparency and oversight, accountability, equality and non-discrimination, privacy, reliability, safe innovation), requires remedies, procedural safeguards and risk and impact assessment, allows moratoria or bans for incompatible uses, and creates a Conference of the Parties for follow-up. National-security activities and defence are excluded.

Adopted 17 May 2024 Verified Official source
India Act / statute Partially applicable Binding

India DPDP Act

Digital Personal Data Protection Act, 2023 and DPDP Rules, 2025

The DPDP Act is India's cross-sector personal-data law. It applies to digital personal data processed in India and to processing outside India connected with offering goods or services to people in India. It requires a lawful basis (consent or specified legitimate uses), notice, purpose limitation, data accuracy, security safeguards, breach notification to the Data Protection Board and affected individuals, and grants rights of access, correction, erasure and grievance redress. Significant Data Fiduciaries face extra duties such as impact assessments and audits. The Act does not mention AI specifically, but it governs the personal data used to train and operate AI systems.

Adopted 11 Aug 2023 Verified Official source
Kazakhstan Act / statute Adopted Binding

Law on Artificial Intelligence (2025)

Law of the Republic of Kazakhstan "On Artificial Intelligence" (signed November 2025)

The law defines AI systems and their classification by level of autonomy and risk, sets principles (legality, fairness, transparency, safety, human control), assigns duties to owners and operators of AI systems including risk management, labelling of AI-generated content and protection of personal data, prohibits certain manipulative and social-scoring uses, provides for a national AI platform and state support measures, and allocates state regulation to the authorised body.

Adopted 17 Nov 2025 Verified Official source
Italy Act / statute In force Binding

Law No. 132/2025 on artificial intelligence

Legge 23 settembre 2025, n. 132 – Disposizioni e deleghe al Governo in materia di intelligenza artificiale

Italy's framework AI law, published in the Official Gazette on 25 September 2025 and in force from 10 October 2025. It states principles (human-centric, transparent, safe AI; protection of fundamental rights), sets sector rules for healthcare (AI as support, not replacement, for clinical decisions), employment (information to workers, an AI-at-work observatory), intellectual professions (client disclosure), justice (judge decides; AI only for organisational support) and public administration, requires parental consent for children under 14, designates AgID and ACN as national authorities, delegates the government to align national law with the EU AI Act, and creates a criminal offence for unlawful dissemination of AI-generated or manipulated content with aggravating circumstances for other crimes committed with AI.

In force 10 Oct 2025 Verified Official source

What can you do with the records?

Four tools built on the same records: map controls to duties, screen which rules may apply to you, compare jurisdictions side by side, and take the data away.

Open source, open data

Records live as reviewable YAML in a public repository. Propose corrections and sources through pull requests, or use the contribution form.

View on GitHub

Export obligations to a workflow tool with Certifyi, a separate compliance execution platform. AIPolicyTracker itself stays open and independent.

Disclaimer: informational only, not legal advice. Verify every claim against the linked official sources and consult a qualified lawyer before acting.

Frequently asked questions

What is an AI policy tracker?

A record of the laws, regulations, national AI policies, strategies and guidance that governments and standards bodies issue about artificial intelligence, kept current as they change. This one also breaks each law into the duties it creates, the deadlines that apply and the controls that meet them, and links every record to its official source.

Is this global AI law and policy tracker free?

Yes. Every page is free to read without an account, the records are open data under CC BY 4.0, the REST API needs no key, and the templates are free to download. Following a record for daily alerts needs a free account.

Is there a map of AI regulations around the world?

Yes. The jurisdictions directory opens with a world map shaded by the strongest AI instrument on record in each country (binding law in force, binding law adopted, or strategy and guidance), and every country links to its page with laws, status and dates.

Which countries and regions does it cover?

Every country with an AI-related record, the European Union and other supranational bodies, and US states and other sub-national jurisdictions with their own rules. A jurisdiction with no AI-specific law is recorded as such rather than left out.

Is there a free AI policy template?

Yes. The templates library has a company AI policy (an acceptable use policy) and an AI governance policy with a RACI, alongside an AI system inventory, risk register, impact assessments and EU AI Act kits, each generated from the recorded duties and free to download.

How current is the information?

Each record shows when its source was published and when it was last checked against it. Changes are logged on the updates page as they are recorded, and a record not re-checked within the verification window is marked stale rather than presented as current.